24 Jan 2008 | By Kristopher | Posted under Backdoors, Worms | No Comments »

Worm_Imbot.AC Threat Level: Worm_Imbot.AC is a Medium Danger

Worm_Imbot.AC is a worm that spreads itself through MSN Messenger and some insecure websites. Worm_Imbot.AC typically sends you an instant message on MSN Messenger, with a .zip file attached. Of course, the attachment is a contains Worm_Imbot.AC. Worm_Imbot.AC’s IM might read:

“Have I shown you this new picture of my cat:)”
“Hey, check out this great photo from my trip to England”
“Did you see this picture, it’s hilarious!!!!!”

I can’t think of any photos great enough to risk downloading Worm_Imbot.AC. Even of Heidi Klum.

Well…

If you’ve ever received a message like that on MSN Messenger, it’s best to stop using MSN until you know you’ve removed Worm_Imbot.AC. Otherwise, Worm_Imbot.AC may connect to TCP ports and let anonymous attackers execute commands on your computer, and kill memory processes.

Keep reading »


11 Oct 2007 | By Kristopher | Posted under Worms | 1 Comment »

Backdoor.Agobot is a family of backdoor worms that spreads itself through peer-to-peer (P2P), file-sharing applications. When Backdoor.Agobot infects your computer, it’ll take commands from an anonymous attacker via IRC to start DoS (Denial of Service) attacks (DoS attacks work by overloading your computer with so much traffic that it crashes). Backdoor.Agobot can also execute commands through cmd.exe, and Agobot rips a security hole into your system, making your financial and personal information insecure. Agobot may also be known as Gaobot, and other bots in the Agabot family include Phatbot, Urxbot, Rbot, Forbot, and Rxbot. Some versions of Agobot can use a keylogger to steal your information. I say remove Backdoor.Agobot and its cousins as fast as you can. The only reason you should download Agobot is to use the application to go after whoever installed it onto your machine, first.

Keep reading »


26 Sep 2007 | By Kristopher | Posted under Worms | No Comments »

Worm.Newbiero Threat Level: Worm.Newbiero is a danger

Worm.Newbiero is a worm that tears a back hole in your system and allows a hacker to access your PC. Worm.Newbiero can infect your computer through open local area networks. Once Worm.Newbiero is on your PC, it starts up with Windows every launch. Worm.Newbiero then allows a hacker to access your PC, launching applications, downloading files, and putting your personal and financial data at risk. Worm.Newbiero will try to disable firewalls such as Sygate Personal Firewall, Tiny Personal Firewall, ZoneAlarm, and ZoneAlarm Pro. Worm.Newbiero can mess up your computer more than your three-year-old nephew banging on your keyboard, so delete Worm.Newbiero immediately.

Keep reading »


26 Sep 2007 | By Kristopher | Posted under Worms | No Comments »

Worm.Skipi.b is a worm targeting popular Internet calling software Skype. Worm.Skipi.b, also known as Pykse, is said to be a worm though it requires some interaction from users. Worm.Skipi.b Skypes messages of links to contacts reaped from an infected PC. Worm.Skipi.b’s Skype messages link to a picture of barely dressed woman, which is displayed while Worm.Skipi.b downloads and installs itself onto a user’s computer. Once Worm.Skipi.b is installed, it may lodge in your registry system and create browser helper objects (BHO) so that it launches at your systems start up. Worm.Skipi.b may then set your Skype status to “Do Not Disturb” so you won’t receive incoming messages while it attempts to infect other users and visit websites.

Keep reading »


04 Aug 2007 | By Kristopher | Posted under Worms | No Comments »

W32.Vispat.B@mm is a worm that harvests email addresses on your PC after you’ve been infected. W32.Vispat.B@mm then emails itself to these email addresses and infects these computers, via its email message titled “Re:Ho sbagliato email,” with the attachment named “fotoamore.zip”, and the message body:

“Dire che sono imbarazzato per l’errore di invio mi sembra scontato…
spero che capirai che quanto
Se vuoi capire di cosa si tratta guarda in allegato o scarica lo zip da qui”
ciao tesoro mio”

W32.Vispat.B@mm may also change your Internet Explorer start page/home page to http://www.katasearch.com/______, and W32.Vispat.B@mm may also lower your security settings for Internet Explorer, putting your PC at risk for further infection.

Keep reading »


23 Jun 2007 | By Kristopher | Posted under Worms | No Comments »

Sober Worm is a worm that spreads itself through email as an attachment, approximately sized 56,808 bytes, with a random name and the file extension .pif, .zip, or .bat. You have to open Sober Worm’s attachment to infect your PC, and once Sober Worm infects your system, Sober Worm may popup a message (”WinZip Self-Extractor, WinZip_Data_Module is missing ~Error:”) and then may scan your system for any email addresses and send itself as an email attachment to these addresses. Sober Worm will save the email addresses it emails in a file named winexerun.dal, winmprot.dal, winroot64.dal, or winsend32.dal. Sober Worm uses its own SMTP engine to send these emails, making it less likely to be detected.

Keep reading »


07 Jun 2007 | By Kristopher | Posted under Worms | No Comments »

Zhelatin.DAM is a worm that spreads itself through email. When you’re infected with Zhelatin.DAM, Netsky may nestle itself in your system using rookit tactics to keep from being detected. Zhelatin.DAM may add your computer to an IRC botnet, and Zhelatin.DAM will harvest email addresses from your computer and spam itself as an attachment to your contacts.

Keep reading »


27 May 2007 | By Kristopher | Posted under Worms | 1 Comment »

Worm.NetSky or Netsky Virus is malware sometimes classified as a worm and virus. Worm.Netsky or Netsky Virus spreads itself through email. When you’re infected with Worm.Netsky/Netsky Virus, Netsky may nestle itself in your registry so that it launches every time you boot up your computer. Netsky duplicates its processes in your system, so that if you delete one Netsky processes the other may function. Worm.Netsky/Netsky Virus will harvest email addresses from your computer and automatically mail itself as an attachment to your contacts. Worm.Netsky/Netsky Virus may also open a backdoor security hole in your PC, so that an anonymous attacker may silently command your PC. It’s recommended your delete Netsky immediately.

Keep reading »


19 Apr 2007 | By Kristopher | Posted under Worms | No Comments »

Pykse is new malware reportedly targeting popular Internet calling software Skype. Pykse, said to be a worm though it requires some interaction from users, Skypes messages of links to contacts reaped from an infected PC. Pykse’s Skype messages link to a picture of barely dressed woman, which is displayed while Pykse downloads and installs itself onto a user’s computer. Once Pykse is installed, it may lodge in your registry system and create browser helper objects (BHO) so that it launches at your systems start up. Pykse may then set your Skype status to “Do Not Disturb” so you won’t receive incoming messages while it attemps to infect other users and visit websites.

Keep reading »


17 Dec 2006 | By Kristopher | Posted under Worms | No Comments »

Stration Worm is a worm that may block your security software, including your antivirus software, firewalls, and more. Stration Worm may also cause Internet Explorer web browser errors, block your using Registry Editor, stop you from saving on NotePad, and download other malware from the Internet. Stration Worm may use your ICQ without your knowledge to infect other computers by sending them links to download Stration Worm. Your computer becomes infected when you click this link and download Stration Worm. Once Stration Worm has infected your computer, the worm may copy itself to your Windows System folder and create files so that it is launched every time you startup your system. When you’re infected with Stration Worm, it’s recommended you delete it immediately.

Keep reading »